Description
Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the input host to be an exact member of SUPPORTED_DOMAINS, and then reuses that input host for API requests. When a Pixeldrain API key is configured, processing a crafted URL from an attacker-controlled lookalike host causes cyberdrop_dl/crawlers/pixeldrain.py to send the Authorization header to that host. The URL may be introduced through a third-party site that can cause downloads for other sites, and the attacker receives the user's Pixeldrain API key. This issue is fixed in version 9.14.0.
Published: 2026-09-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure: User API key
Action: Patch
AI Analysis

Impact

The vulnerability arises from the Pixeldrain crawler using substring matching for host validation instead of requiring exact domain matches. An attacker who controls a look‑alike host can supply a crafted Pixeldrain URL, which may be introduced via a third‑party site that triggers downloads for other sites. This causes the crawler to treat the fake host as supported and to send the user's Pixeldrain API key in an Authorization header to that malicious host, thus allowing the attacker to obtain the sensitive credential. This is an input validation failure (CWE‑20) that results in information disclosure (CWE‑200).

Affected Systems

Affected installations are Cyberdrop‑DL versions ranging from 8.5.0 up through, but not including, 9.14.0. Users running these versions with a Pixeldrain API key and with the Pixeldrain crawler enabled are at risk, regardless of whether the user accesses the program locally or through a third‑party site that can trigger downloads. The problem is mitigated in the 9.14.0 release.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. An attacker can construct a look‑alike domain and host a malicious site that induces users to launch Cyberdrop‑DL. If a user has the API key configured, the key will be sent to the attacker’s domain during normal operation, exposing the credential.

Generated by OpenCVE AI on September 17, 2026 at 16:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Cyberdrop‑DL to version 9.14.0 or later, which removes the vulnerable substring matching logic.
  • If upgrading is not immediately possible, disable the Pixeldrain feature or configure the program so that no API key is stored or used.
  • Configure a strict host whitelist or additional input validation to ensure incoming URLs match the exact SUPPORTED_DOMAINS entries before forming API requests.

Generated by OpenCVE AI on September 17, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f5pf-q7c7-m3vv Pixeldrain API key shared with unverified thirdparty sites
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cyberdrop-dl
Cyberdrop-dl cyberdrop-dl
Vendors & Products Cyberdrop-dl
Cyberdrop-dl cyberdrop-dl

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the input host to be an exact member of SUPPORTED_DOMAINS, and then reuses that input host for API requests. When a Pixeldrain API key is configured, processing a crafted URL from an attacker-controlled lookalike host causes cyberdrop_dl/crawlers/pixeldrain.py to send the Authorization header to that host. The URL may be introduced through a third-party site that can cause downloads for other sites, and the attacker receives the user's Pixeldrain API key. This issue is fixed in version 9.14.0.
Title Cyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sites
Weaknesses CWE-20
CWE-200
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cyberdrop-dl Cyberdrop-dl
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T16:03:21.234Z

Reserved: 2026-06-12T16:25:43.086Z

Link: CVE-2026-54254

cve-icon Vulnrichment

Updated: 2026-09-16T16:03:17.285Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:18.170

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:58:56Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor